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It is the first scheme which allows the detection apparatus to achieve both the photon number of 
arriving signals and quantum bit error rate of the multiphoton pulses precisely. We show that the 
upper bound of the fraction of the tagged multiphoton pulses counts is fi, which is independent of 
the channel loss and the intensity of the decoy source. Such upper bound is inherent and cannot be 
reduced any longer as long as the weak coherent scouces and high lossy channel are used. We show 
j^-^ | that our scheme can be implemented even if the channel loss is very high. A stronger intensity of the 

■ pulse source is allowable to improve the rate of quantum key distribution. Both the signal pulses and 
decoy pulses can be used to generate the raw key after verified the security of the communication. 

CN) , We analyze that our scheme is optimal under today's technology. 
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\q • Quantum key distribution (QKD) is a physically secure method, by which private key can be created between two 
j partners, Alice and Bob, who share a quantum channel and a public authenticated channel [1]. The key bits then be 
used to implement a classical private key cryptosystem, or more precisely called one — time pad algorithm, to enable 
' the partners to communicate securely. 

An optical QKD system includes the photon sources, quantum channels, single-photon detectors, and quantum 
random-number generators. In principle, optical quantum cryptography is based on the use of single-photon Fock 
, states. However, perfect single-photon sources are difficult to realize experimentally. Practical implementations rely 
on faint laser pulses in which photon number distribution obeys Possionian statistics. So, Eve can get benefits from 
the multiphoton pulses. If the quantum channel is high lossy, Eve can obtain full information of the final key by using 

■ photon number splitting (PNS) attack without being detected. In GLLP [2], it has been shown that the secure final 
CD key of BB84 protocol [3] can be extracted from sifted key at the asymptotic rate 

Ph! R=(l-A)-H 2 (e)-(1-A)H 2 ( T ^ X ), (1) 

where e is the quantum bit error rate (QBER) found in the verification test and A = pm/pd, where pm is the 
probability of detecting a multiphoton pulse and po is the probability that an emitted photon is detected. This 
means that both the QBER e and the fraction of tagged signals A are important to generate the secure final key. It 
has been shown that Eve's PNS attack will be limited when Alice and Bob use the decoy-state protocols [4-6]. In such 
decoy-state protocols, the detection apparatus cannot resolve the photon number of arriving signals. Thus, Eve may 
use a photon number splitting and resending (PNSR) attack on the multiphoton pulses, i.e., Eve replaces one photon 
of the multiphoton pulses by a false one and forwards the pulses to Bob, to eavesdrop Alice's information. Therefore, 
it requires that the communication partners should have the capacity to achieve the QBERs of multiphoton pulses. 
As a matter of fact, Eve's some other attacks, such as coherent multiphoton pulse attack, should also be considered 
or else security of the final key will be unreliable. 

In this paper, we present an experimental detection apparatus which allows Bob to achieve the photon number of 
arriving signals and QBER of the multiphoton pulses precisely. The upper bound of the information Eve can gain 
from channel loss is fi, no matter how high the channel loss is. We show that all the multiphoton pulses verified by 
Bob should be discarded in the end. As a consequence, security of the QKD is only determined by the QBER and 
the intensity of the pulse sources fi, irrespective of the channel loss efficiency and the intensity of the decoy sources. 
Finally, we discuss and conclude that our scheme is optimal under today's technologies. 

At present, practical "single- photon" sources rely on faint laser pulses in which photon number distribution obeys 
Possionian statistics. Most often, Alice sends to Bob a weak laser pulse in which she has encoded her bit. Each 
pulse is a priori in a coherent state \^/jLe ie ) of weak intensity. Since Eve and Bob have no information on 9, the state 
reduces to a mixed state p = J ^\^e l6 ){^/Jle tS \ outside Alice's laboratory. This state is equivalent to the mixture of 
Fock state J2 n Pn\ n )( n \' w ^ n * ne number n of photons distributed as Possionian statistics p n = P M (n) = /i' l e _A1 /n!. 
The source that emits pulses in coherent states \^[Jie ie ) is equivalent to the representation as below: With probability 
Po, Alice does nothing; With probability p n (n > 0), Alice encodes her bit in n photons. Thus, Eve can use 
two different eavesdropping strategies to gain information about Alice's qubit. Eve first performs a nondemolition 



1 



measurement to gain the photon number of the laser pulses. When she finds there is only one photon in the pulses, 
she implements symmetric individual (SI) attacks to gain Alice's information [7]. Otherwise, if there are two or more 
than two photons in the pulses, she will perform some multiphoton attacks on Alice's qubit, e.g., she may implement 
PNS attack on Alice's qubit. The probability of that a nonempty pulse contains more than one photon is that 
p(n > l|n > 0,/i) — 1 ~p(°^^)~p( 1 'A') _ i-ej^(i+;x) ~ M. it is a fact that the probability of p(n > l\n > Q,fi) can be 
made arbitrary small so that weak pulses are practical and have indeed been used in the vast majority of experiments 
[1]. However, in long distance QKD, the channel transmittance 77 [8] can be rather small. If 77 < (1 — — /ie~ M )//i, 
Eve can gain full information of Bob's final key by using the PNS attack [9]. 

Photon number measurement and QBERs of multiphoton pulses. — In Fig. 1, we present a method to obtain the 
photon number of the multiphoton pulses. Furthermore, QBERs of different multiphoton pulses can also be achieved. 
In Fig. 1(A), there are N beam splitters (BSs) at the end of the fiber. The probability that two photons were detected 
in one single-photon detector is approximate to 0(1/N) [10]. Bob can perfectly achieve the photon number of the 
multiphoton pulses by increasing the number of the BS. In Fig. 1(B), there is a polarization beam splitter (PBS) 
at each output of each BS. Obviously, these PBSs should be parallel. Using Alice's public announcement, Bob can 
obtain the QBER with his statistic data. In an uncharacteristic channel, all QBERs of different multiphoton pulses 
should be identical. Thus, if cither the photon number statistics results or the QBER is abnormal, Alice and Bob will 
know that Eve is in line. 

Eavesdropping hidden in channel losses. — In order to detect Eve's PNS attack, Alice and Bob will use the 
improved decoy-state protocol to verify the security of their communication. Suppose Alice and Bob select n as 
signal source and n 1 as the decoy source in our scheme. Without Eve's presence, photon number distributions arc 
also Poissonian with the channel transmittance 77, 

p Ls(n)= { ^e^\ (2) 
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In general, let us assume that Eve has a lossless quantum channel. She implements PNS attack on the photon pulses 
with probability P Ev e (n) ■ Essentially, the idea of decoy-state is that [6] 

P Ev e(signal) = P Ev e(decoy) = P Ev e(n) (4) 
e n (signal) = e n (decoy) = e n . (5) 

The sufficient condition that Eve can redistribute the photon number without being detected is that 

P»[l - P Eve (n)] + P"(n + l)P Eve (n + 1) = P£,», (6) 
P"'(n)[l - P Eve (n)] + P"'(n + l)P Eve (n + 1) = P/f s » (7) 

are satisfied for all n with P Eve (0) = 0. PE„ e (l) implies that Eve blocks some single photon pulses to satisfy P;q SS (0). 
Clearly, P Eve (n) should be independent of a because of the decoy source fi', vice versa. Solution of PE„ e (l) is that 

e -w _ e -M 

PEve(l) = =— = 1~V, (8) 

fie f 

where we assumed that e^ 1 ^^ = 1 + /j(1 — rj) + 0{p?) because /1 is small. This implies that the distribution of photon 
number in Bob's detection apparatus can be satisfied when Eve blocks the single photon pulses with the probability 
1 — t), i.e., transmittance efficiency of single photon pulses is 77 on this occasion. From the equation 

/^-"[l - P Eve (l)} + P Eve (2)^e-» = i,^, (9) 

we can obtain that 

P Eve (2) = 2(1 - 77)77, (10) 

which is also independent of u. That is, if Eve can perform the PNS attack with the probability 2(1 — 77)77 on the 
two-photon multiphoton pulses to satisfy the single-photon distribution on Bob's detection apparatus. However, one 
can obtain that 



2 



(11) 



That is, even all the three-photon multiphoton pulses are blocked, the probability that Bob detects two-photon 
multiphoton pulses will be abnormally higher. Eve has to block both of the two photons of two-photon multiphoton 
pulses with the probability (1 — n) 2 . Thus, the probability that both of Alice's two photons can be detected in Bob's 
detection apparatus is n 2 . Eve's such attacks are equivalent to that Eve attacks every photon with the probability 
1 — n no matter which pulses it belongs to. In this way, we can obtain all PEve{n) uniquely [11]. Moreover, such 
PEve( n ) are independent of the intensity of the pulses sources. That is, decoy-state protocols are inefficient on this 
occasion. In this case, such attacks are inevitable as long as the channel is lossy. It is the inherent property of the 
QKD with weak coherent source and lossy channel. 

From the discussion above, we know that the fraction of the two-photon pulses that can be used by Eve is that 
PEve(2) — 2(77 — rj 2 ). Since most of the multiphoton pulses are two-photon pulses, we can obtain that 

A=^"-" 2 ><„. ,12, 
V 

In practical long distance QKD, 77 is very small. Thus, the upper bound of the fraction of the multiphoton pulses that 
Eve can gain information without being detected is yu, which is independent of the channel loss and the intensity of 
the decoy sources. Consequently, our scheme can be applied no matter how high the channel loss is. If Alice and Bob 
verified the absence of Eve, i.e., both the QBER and photon number distributions are normal, they can use both the 
decoy pulses and signal pulses to generate their raw key. 

Another question is that Eve may use PNSR attack on the multiphoton pulses. Without doubt, Eve's PNSR attack 
would cause some additional bit error rate of the multiphoton pulses. Fortunately, our scheme is sensitive to the bit 
error rate of multiphoton pulses e n [12]. Therefore, our scheme is sensitive to Eve's PNSR attack. 

Optimal eavesdropping scheme. — In a general way, we will assume that Eve's ability is only limited by the 
principles of quantum mechanics. It is allowable that Eve holds a lossless channel and a perfect quantum memory 
Therefore, Eve can get benefits from noises and channel loss. In order to avoid being detected, Eve will hide all 
of her attacks in the QBER or in the channel loss. On the other hand, with the same QBER, Eve can get more 
benefits from the multiphoton pulses than that from the single photon pulses [13]. If Alice and Bob can discard 
some of the multiphoton pulses, security of the communication will be enhanced. Bob can find out which pulses are 
multiphoton pulses in our scheme. He labels such multiphoton pulses and discards them. The probability that Bob 
detects a multiphoton pulse is e ^r/ 2 / pp « i^n/2. Therefore, the optimal eavesdropping scheme Eve may use 
can be described as follow. Eve implements SI attack on the single photon pulses. She captures every photon with 
probability 1 — n in her perfect channel. In this case, the maximal information Eve can gain is given by 

I AE =p S iH SI + Ptagged . (13) 

The probability of the fraction of tagged multiphoton is that ptagged = M- The probability that Eve uses a SI attack 
is that psi = 1 — Ptagged [14]. In this way, Eve can attack on the communication optimally without being detected. 

In one way communication, the final key is secure if and only if I AB > I AE . In fact, I AB is determined by the 
unique variable QBER since I AB = 1 — h (e), where h(x) = —xlog 2 x — (1 — x) log 2 (l — x). The maximal information 

Eve can gain by using SI attack is given by Hsi = 1 — h ^ 1+2 ^ e ~ — ^ [15]. In general, security of the final key is 

determined by the parameter u, u', and e. We give a numerical solution of the security with different u and variational 
e in Fig. 2. 

Discussion and conclusion. — Today, quantum key distribution over 150 km of commercial Telcom fibers has 
been successfully performed. The crucial issue in QKD is its security. Experimentally, the source is imperfect and 
the channel is lossy and noisy. In our experimental scheme, both photon number of arriving signals and QBER can 
be achieved precisely. We showed that the upper bound of information Eve can gain from in the channel loss is 
independent of n and u' [17], so that our scheme can be used even if the channel loss is very high. In our scheme, 
information Eve can gain is only determined by QBER and u. As a matter of fact, Eve's such information can not 
be reduced any longer as long as the weak coherent sources and imperfect quantum channel are used in long distance 
QKD, so that our scheme is optimal under today's technology. 

In summary, we have discussed the security of practical BB84 QKD protocol with weak coherent sources, noises 
and high losses. We have presented a detection apparatus to resolve both the photon number of arriving signals and 
QBER to beat Eve's whatever PNS attacks. Our scheme is efficient even if the channel loss is very high. Both the 
signal pulses and decoy pulses can be implemented to generate the raw key after verified the security of the QKD. A 
bigger a is allowable to improve the rate of generating the raw key. We have discussed that our scheme is optimal 
under today's technology. 
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NOTE. — After finished our work, we find out the paper [18] which presented an experimental photon number 
resolving scheme using time-multiplex technique. However, our scheme not only can be used to resolve the photon 
number of multiphoton pulses, but also can be used to achieve the QBER of multiphoton pulses. 

The author wishes to thank Yong-gang Tan and Qiang Liu for their useful discussions and comments. Yong Li 
should be thanked specially. This work is supported by National Nature Science Foundation of China under Grant 
No. 10447140. 
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II. CAPTIONS 

Caption 1. FIG. 1. Outline of Bob's detection apparatus. In order to obtain the photon number of an arriving 
laser pulse, Bob first sets a group of parallel beam splitter (BS) behind the fiber. Every BS was set at the output of 
the frontal BS. Since there are two outputs of each BS, the number of BS increases exponentially as Bob's photon 
number resolving power increases. Assume the number of BS Bob used is N. Then the photon number resolving 
power of Bob's apparatus (in A) is approximate to 0(1/N). The apparatus in B will be used to obtain the states of 
the qubit Alice sent. A group of parallel polarization beam splitter (PBS) was set in the output of each BS. There is 
a single-photon detector (SPD) at each output of the PBS. Using such apparatus, photon number of arriving signal 
can be resolved and a precise QBER can be achieved. 

Caption 2. FIG. 2. Eve's and Bob's information vs the QBER. I AB is information Bob can gain with the QBER. 
I AE is the information. The point at which privacy amplification can be implemented is that QBER=13.5% (/i = 0.1), 
QBER=12.1% (fi = 0.2), and QBER=10.7% (fi = 0.3). Thus, a bigger \x is allowable in our scheme. Moreover, both 
the signal pulses and decoy pulses can be used to generate the raw key. Although error-correcting can be performed 
as long as the QBER is lower than 11% [16], a small [i and a lower QBER will improve the rate of generating the 
final key from the sifted key [2] . 
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